Privacy Policy

Last updated: April 12, 2026

1. Who We Are

Repetrax is a solo indie product operated by an individual based in Lithuania. The service is available at repetrax.com (marketing site) and app.repetrax.com (web app), with iOS and Apple Watch apps coming soon. For privacy-related questions, contact info@repetrax.com.

2. Data We Collect

We collect only what is necessary to provide the service:

  • Account information — email address, display name, and a hashed password (never stored in plaintext)
  • Study activity — flashcard review sessions, card ratings, streaks, review history, and timezone preference
  • Imported media — audio and image files from Anki deck imports, stored on Amazon S3
  • Billing identifiers — Stripe customer ID and subscription ID. We never store card numbers or full payment details; those are handled entirely by Stripe

3. Legal Basis for Processing

We process your personal data on the following legal bases under GDPR Article 6:

Contract (Art. 6(1)(b)) — account information and study activity are processed to deliver the service you signed up for.
Legal obligation (Art. 6(1)(c)) — billing identifiers and financial records are retained as required by tax and accounting law.
Legitimate interests (Art. 6(1)(f)) — anonymous performance metrics (Vercel Analytics) are processed to maintain and improve the service.
Consent (Art. 6(1)(a)) — Google Analytics is only active after you accept cookies via the Cookiebot banner. You may withdraw consent at any time.

4. How We Use Your Data

  • Authenticate your account and sync progress across devices
  • Schedule flashcard reviews using spaced-repetition algorithms
  • Process subscription payments and manage your plan
  • Send transactional emails (e.g. password reset, billing receipts)
  • Understand aggregate usage patterns to improve the service

We do not sell your data to third parties.

5. Third-Party Data Processors

We use the following sub-processors to operate the service. Each receives only the data necessary for their function:

Neon (PostgreSQL)

Hosts the primary database in the EU. Stores account data, study history, and flashcard content.

Vercel

Hosts the web application and marketing site via EU edge nodes. May process request metadata (IP, user-agent) in transit. Data transfers outside the EEA are covered by Standard Contractual Clauses.

Amazon S3 (eu-north-1, Stockholm)

Stores media files (audio, images) uploaded via Anki imports. Files are scoped to your account and stored within the EU.

Stripe

Processes subscription and one-time payments. Stripe stores your payment method and billing details under their own privacy policy. We only hold your Stripe customer ID and subscription ID. Data transfers outside the EEA are covered by Standard Contractual Clauses.

Google Analytics (GA4)

Collects page-view and interaction analytics on repetrax.com, only with your consent. Data may be processed in the United States under Standard Contractual Clauses. Consent is managed via Cookiebot.

Cookiebot

Manages cookie consent on the website. Records your consent preferences.

Vercel Analytics & Speed Insights

Collects anonymous performance and usage metrics. No personally identifiable information is shared. Data transfers outside the EEA are covered by Standard Contractual Clauses.

6. Cookies

We use cookies for authentication sessions and, with your consent, for analytics (Google Analytics). You can manage or withdraw cookie consent at any time via the cookie banner on the site.

7. Data Retention

Your data is retained for as long as your account is active. You may delete your account at any time — this permanently removes all associated data (flashcard decks, study history, media files, and billing identifiers) from our systems within 30 days. Financial records (e.g. payment identifiers linked to transactions) may be retained for up to 7 years where required by Lithuanian tax and accounting law.

8. Your Rights (GDPR)

If you are located in the European Economic Area, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and all associated data
  • Receive your data in a portable, machine-readable format
  • Object to or restrict certain processing
  • Withdraw consent for analytics at any time (without affecting prior processing)
  • Lodge a complaint with the Lithuanian Data Protection Authority (vdai.lrv.lt)

To exercise any of these rights, contact info@repetrax.com. We will respond within 30 days.

9. Changes to This Policy

If we make material changes to this policy, we will notify you by email or via an in-app notice at least 14 days before the changes take effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.